Description
Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/07/27/1
https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2686
Related Vulnerabilities
CVE-2018-1002204 Vulnerability in maven package org.webjars:adm-zip
CVE-2020-2165 Vulnerability in maven package org.jenkins-ci.plugins:artifactory
CVE-2019-10381 Vulnerability in maven package org.jenkins-ci.plugins:codefresh
CVE-2023-31065 Vulnerability in maven package org.apache.inlong:manager-web
CVE-2022-24717 Vulnerability in npm package @finastra/ssr-pages